New Windows Service Installation - Persistence or Malicious Driver

This rule detects the installation of a new Windows service by monitoring Security Event IDs 4697 and 601. It extracts details about the service name, file path, and account used. The rule flags services that have suspicious binary paths, such as those within user-writable directories (Temp, AppData, Downloads) or paths containing common living-off-the-land binaries, which may indicate persistence or the loading of malicious drivers.